bug-wget
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Bug-wget] Wget 1.11.4 (symlink bug)


From: address@hidden
Subject: [Bug-wget] Wget 1.11.4 (symlink bug)
Date: Tue, 21 Apr 2009 17:56:49 +0300
User-agent: Thunderbird 2.0.0.21 (Windows/20090302)

uname -a
FreeBSD xxx.kiev.ua 7.1-RELEASE FreeBSD 7.1-RELEASE #0: Fri Apr 3 12:01:37 EEST 2009 address@hidden:/usr/src/sys/amd64/compile/GENERIC amd64


wget -V
GNU Wget 1.11.4

Copyright (C) 2008 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later
<http://www.gnu.org/licenses/gpl.html>.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

Originally written by Hrvoje Niksic <address@hidden>.
Currently maintained by Micah Cowan <address@hidden>.





chmod symlink vulnerability where when invoked with the -N option, it
tries to chmod downloaded symlinks, but actually permissions are changed at target files. There is the potential to chmod target files to world-writable.



DEBUG output created by Wget 1.11.4 on freebsd7.1.

Using `ftp.liga.net/liga-updates/news/.listing' as listing tmp file.
--2009-04-21 16:16:01-- ftp://5081wCzR:address@hidden/liga-updates/news/
           => `ftp.liga.net/liga-updates/news/.listing'
Resolving ftp.liga.net... 193.17.46.21
Caching ftp.liga.net => 193.17.46.21
Connecting to ftp.liga.net|193.17.46.21|:21... connected.
Created socket 4.
Releasing 0x00000008011080a0 (new refcount 1).
Logging in as 5081wCzR ... 220 --------- Welcome to Pure-FTPd [TLS] ----------

[skipped]

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254451.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254452.bbs -> ../2009-03-19/nws254452.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254452.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254453.bbs -> ../2009-03-19/nws254453.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254453.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254454.bbs -> ../2009-03-19/nws254454.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254454.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254455.bbs -> ../2009-03-19/nws254455.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254455.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254456.bbs -> ../2009-03-19/nws254456.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254456.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254457.bbs -> ../2009-03-19/nws254457.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254457.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254458.bbs -> ../2009-03-19/nws254458.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254458.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254459.bbs -> ../2009-03-19/nws254459.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254459.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254460.bbs -> ../2009-03-19/nws254460.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254460.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254461.bbs -> ../2009-03-19/nws254461.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254461.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254462.bbs -> ../2009-03-19/nws254462.bbs

Unrecognized permissions for ftp.liga.net/liga-updates/news/all/nws254462.bbs. Already have correct symlink ftp.liga.net/liga-updates/news/all/nws254463.bbs -> ../2009-03-19/nws254463.bbs


[skipped 300.000 lines]
and than ...

Unrecognized permissions for ftp.lig



Core dumped





--






reply via email to

[Prev in Thread] Current Thread [Next in Thread]